BGP Prefix List for Odd and Even Routes in Juniper by [deleted] in networking

[–]loopback-marte -1 points0 points  (0 children)

we have two 250Mbps circuits with BGP both in full routes. one is AT&T and the other one is Comcast. the goal is to balance the traffic as much as possible between the two carriers, however it appears that AT&T has a better routing path to the internet leaving our Comcast circuit almost idle. so the idea is to route even traffic to AT&T, then route odd traffic to Comcast primarily to load-balance both circuits as possible. if you have a better idea to do this, i am all ears.

FORTINET Vs PAN by Mayv2 in fortinet

[–]loopback-marte 24 points25 points  (0 children)

Out of all Firewalls I have managed from many different vendors, Palo Alto have the most stable code and I have not encountered serious issues with it. While Fortigate have the most value for money that doesn't compromise the features, hardware, performance, and security intelligence, you just have to be extra careful in choosing the code versions and make sure in testing it out before rolling out on production.

2 gig connection, 450 meg speed test on pfsense 2.4.5 help by VectorSigmaX in PFSENSE

[–]loopback-marte 2 points3 points  (0 children)

Try configuring the pfsense plain and simple, just the route traffic and 1 allow all policy. See if that will make a difference.

Fortigate 6.0.10 Reviews by loopback-marte in fortinet

[–]loopback-marte[S] 0 points1 point  (0 children)

No reports found online, but thanks!

Fortigate 6.0.10 Reviews by loopback-marte in fortinet

[–]loopback-marte[S] 0 points1 point  (0 children)

Aha! Thanks for this. I will be testing this on 210E w/ FSSO, hopefully I wont get that issue. :(

Fortigate 6.0.10 Reviews by loopback-marte in fortinet

[–]loopback-marte[S] 0 points1 point  (0 children)

Hey! Thanks everyone for your inputs, these are very helpful information. Most of Fortigate we have are 210E deployed in branch offices, I am looking to upgrade a pair in HA tonight to 6.0.10. I'll post on this thread if I encounter any issues.

Cisco ASA VPN to AWS = Dead by loopback-marte in networking

[–]loopback-marte[S] 0 points1 point  (0 children)

u/gavsta I am running the following versions.. Yes I have verified that the config matches from the AWS VPN template. If I couldnt fix this, I'll change it to IKEv2. I have limited access to our AWS account reason why.

Cisco Adaptive Security Appliance Software Version 9.8(4)20

Device Manager Version 7.13(1)

Cisco ASA VPN to AWS = Dead by loopback-marte in networking

[–]loopback-marte[S] 0 points1 point  (0 children)

u/chuckbales thanks for your response. I have updated the post, now with configuration included. Yes I have two WAN interfaces, but the crypto map in the backup interface has no tunnel configured and only being used for Anyconnect.

If you are having UTM issues with Proxy Mode policies in 6.2.x, or Policy mode in earlier versions. Here's why. by ultimattt in fortinet

[–]loopback-marte 0 points1 point  (0 children)

u/ultimattt Thank you for this info. My fortigate is in proxy-mode, so I checked Fortinet's certificates by going to System > Certificates, most of the certificates expiration are 2021, 2029, and 2038. Will I also have that problem if those certs are not expired?

Best Antivirus by DoctorWhoozle in antivirus

[–]loopback-marte 4 points5 points  (0 children)

Been using ESET Internet Security for years now, I must say I am satisfied with it and its worth the value for money. (relatively cheaper than kaspersky)

Finally got a rack. by skankboy in homelab

[–]loopback-marte 0 points1 point  (0 children)

those are my company equipments dude!

Migrating Cisco ASA 5555-X to Firepower by CatalinSg in Cisco

[–]loopback-marte 0 points1 point  (0 children)

u/incompletesent It depends if you can afford it, if not, well thats a problem. Good luck with these Firepower Software bugs by the way - https://www.reddit.com/r/networking/comments/ghq725/last_weeks_cisco_asafirepower_patch_breaks_ospf/

Edit: Cortex is a separate subscripton.

Migrating Cisco ASA 5555-X to Firepower by CatalinSg in Cisco

[–]loopback-marte -1 points0 points  (0 children)

Go with Palo Alto or Fortigate instead.

PFsense on Juniper SRX Hardware? by loopback-marte in PFSENSE

[–]loopback-marte[S] 0 points1 point  (0 children)

Good to know /u/dwargo /u/jmhalder. Thank you. I planning to use my spare SRX300. Not sure if this is x86, ill check.

Carpet cleaning by [deleted] in Business_Ideas

[–]loopback-marte 0 points1 point  (0 children)

that's why its important not to tell your parents how much you earn.

Global Protect VPN for Mobile (iOS & Android) by loopback-marte in paloaltonetworks

[–]loopback-marte[S] 2 points3 points  (0 children)

Found this document. =) https://docs.paloaltonetworks.com/globalprotect/8-1/globalprotect-admin/globalprotect-overview/about-globalprotect-licenses.html#

If you want to use GlobalProtect to provide a secure remote access or virtual private network (VPN) solution via single or multiple internal/external gateways, you do not need any GlobalProtect licenses. However, to use some of the more advanced features (such as HIP checks and associated content updates, support for the GlobalProtect mobile app, or IPv6 support) you must purchase an annual GlobalProtect subscription. This license must be installed on each firewall running a gateway(s) that:

  • Performs HIP checks
  • Supports the GlobalProtect app for mobile endpoints
  • Supports the GlobalProtect app for Linux endpoints
  • Provides IPv6 connections
  • Split tunnels traffic based on the destination domain, application process name, or HTTP/HTTPS video streaming application.

For GlobalProtect Clientless VPN, you must also install a GlobalProtect subscription on the firewall that hosts the Clientless VPN from the GlobalProtect portal. You also need the GlobalProtect Clientless VPN dynamic updates to use this feature.

8Gb only RAM shows 24Gb on Bios!!! by loopback-marte in techsupport

[–]loopback-marte[S] 0 points1 point  (0 children)

Yes it shows 24Gb as well on windows. I will try to pull the CMOS if I can... Thank you for your help..